So RFC 6979 is fine, but k=HMAC-SHA-256(x,m) is not a secure choice for 256-bit elliptic curves over random base fields.
So RFC 6979 is fine, but k=HMAC-SHA-256(x,m) is not a secure choice for 256-bit elliptic curves over random base fields.
Complaining to the implementers has just resulted in <whine>thats more complicated, mod is fine</white> And, indeed, for secp256k1 the differences is 1 part in 10^38, so its not likely of practical importance; unless you can assume an attack that can extract an _awful_ lot of signatures from you.
I expect the same behaviours are common for different parameters where it's not such a small bias.
But careful approaches like RFC 6979 are very important for curves over random fields, like the Brainpool parameters.
[By the way, a more regular contributor of this site suggested that it would be appropriate for me to mention that I'm one of the authors of the OP.]